A single maintainer and no security policy leave limited visible support if problems arise. The package is clearly identified, licensed, documented, and uses lightweight build and security tooling.
61%
Total Score
50
100
89
75
One registry maintainer indicates a thin publishing base; the repository is user-owned rather than organization-backed, so there is no provided compensating organizational capacity.
The repository is owned by an individual matching the registry namespace, which supports direct ownership but provides no evidence of broader project backing.
The package is young at 298 days and has only three releases, all within a short initial burst; this provides limited evidence of long-term maintenance.
There were no commits and no active maintainers during the last three months, which materially raises concern about maintenance continuity for a package released less than a year ago.
The repository has zero stars, forks, and watchers, offering no supporting evidence of community adoption or external review; this is a secondary caution rather than a decisive risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.